logo

Experts Find Flaw in Replicate AI Service Exposing Customers' Models and Data

ID: f8dd6795-4fd6-51dd-990e-b701fddceb80

STIX ID: report--f8dd6795-4fd6-51dd-990e-b701fddceb80

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-25

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed a critical flaw in AI-as-a-service provider Replicate in which malicious models packaged via the Cog tool could achieve remote code execution and abuse a centralized Redis queue to perform cross-tenant attacks, potentially exposing private models, prompts, and PII; Wiz demonstrated the technique, Replicate patched the issue after responsible disclosure in January 2024, and there is no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.